An ESXi host is marked with an alarm stating "ESXi Host Certificate Status" in the vSphere Client. This occurs when the host's SSL certificate is nearing or past its expiration date.
ESX 7.x
ESX 8.x
ESX 9.x
vCenter Server monitors all certificates within the VMware Endpoint Certificate Store (VECS). It triggers a Certificate Status alarm (typically 30 days prior to expiry) if any host certificate is close to expiration.
For a certificate that is Near Expiry, use the Certificate Management capability within VCF Operations to refresh the certificate.
Follow these steps to renew certificates using the VMware Certificate Authority (VMCA):
If the host is disconnected or the UI is unresponsive, use an SSH session:
/sbin/generate-certificates/etc/init.d/hostd restart/etc/init.d/vpxa restartBefore attempting to renew or refresh ESXi SSL certificates, you must verify the following:
MACHINE_SSL_CERT must be valid.Refer to KB Configuring CA signed certificates for ESXi hosts.